Skip to content

Text · Comparison of two versions

Changes from plenary report to adopted text

A-9-2023-0409 → TA-9-2024-0376

From
A-9-2023-0409 Plenary report of 7 Dec 2023
To
TA-9-2024-0376 Adopted text of 25 Apr 2024
Changes
Not comparable
Paragraphs
+9 added · −158 removed · 1 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on the collection and transfer of advance passenger information (API) for enhancing and facilitating external border controls, amending Regulation (EU) 2019/817 and Regulation (EU) 2018/1726, and repealing Council Directive 2004/82/EC
Title (to)
Advance passenger information: enhancing and facilitating external border controls

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 2 of 4: Paragraphs 61–120

RemovedArticle 3 – paragraph 1 – point h: (h) ‘passenger’ means any person, excluding members of the crew unless they are off duty, carried or to be carried in an aircraft with the consent of the air carrier, such consent being manifested by that person's registration in the passengers list;

RemovedArticle 3 – paragraph 1 – point j: deleted

RemovedArticle 3 – paragraph 1 – point k: (k) ‘Advance Passenger Information data’ or ‘API data’ means the passenger data and the flight information referred to in Article 4(2) and (3) respectively;

RemovedArticle 3 – paragraph 1 – point l: (l) ‘Passenger Information Unit’ or ‘PIU’ means the competent authority referred to in Article 3, point k, of Regulation (EU) [API law enforcement];

RemovedArticle 4 – paragraph 1: 1. Air carriers shall collect API data of passengers, consisting of the passenger data and the flight information specified in paragraphs 2 and 3 of this Article, respectively, on the flights referred to in Article 2, for the purpose of transferring that API data to the router in accordance with Article 6. Where the flight is code-shared between one or more air carriers, the obligation to transfer the API data shall be on the air carrier that operates the flight.

RemovedArticle 4 – paragraph 2 – introductory part: 2. The API data shall consist only of the following passenger data relating to each passenger on the flight:

RemovedArticle 4 – paragraph 2 – point e: deleted

RemovedArticle 4 – paragraph 2 – point g: (g) the number of the seat in the aircraft assigned to a passenger, where the air carrier collects such information;

RemovedArticle 4 – paragraph 2 – point h: (h) number and the weight of checked bags, where the air carrier collects such information.

RemovedArticle 4 – paragraph 3 – introductory part: 3. The API data shall also only consist of the following flight information relating to the flight of each passenger:

RemovedArticle 4 – paragraph 3 – point a: (a) the flight identification number or, where the flight is code-shared between one or more air carriers, the flight identification numbers, or, if no such number exists, other clear and suitable means to identify the flight;

RemovedArticle 5 – paragraph 1 – subparagraph 1 a (new): The collection of API data in accordance with the first subparagraph shall not include an obligation for air carriers to check the travel document at the moment of boarding the aircraft or an obligation for passengers to carry a travel document when travelling, without prejudice to acts of national law that are compatible with Union law.

RemovedArticle 5 – paragraph 2 – subparagraph 1: Air carriers shall collect the API data referred to in Article 4(2), points (a) to (d), using automated means to collect the machine-readable data of the travel document of the passenger concerned. Air carriers shall collect that data during the check-in process, either as part of the online check-in or as part of the check-in at the airport. They shall do so in accordance with the detailed technical requirements and operational rules referred to in paragraph 4, once such rules have been adopted and are applicable, and, in particular, by using the most reliable automated means available to collect the machine-readable data of the respective travel document.

RemovedArticle 5 – paragraph 2 – subparagraph 1 a (new): The collection of API data by automated means shall not lead to the collection of any biometric data from the travel document.

RemovedArticle 5 – paragraph 2 – subparagraph 1 b (new): Where air carriers provide an online check-in process, they shall enable passengers to provide the API data referred to in Article 4(2), points (a) to (d), during the online check-in process, using automated means.

RemovedArticle 5 – paragraph 2 – subparagraph 2: However, where such use of automated means is not possible, air carriers shall collect that data manually either as part of the online check-in or as part of the check-in at the airport, in such a manner as to ensure compliance with paragraph 1.

RemovedArticle 5 – paragraph 3: 3. Any automated means used by air carriers to collect API data under this Regulation shall be reliable, secure and up-to-date. Air carriers shall ensure that API data is encrypted during the transmission of the data from the passenger to the air carriers.

RemovedArticle 5 – paragraph 4: 4. The Commission is empowered to adopt delegated acts in accordance with Article 37 to supplement this Regulation by laying down detailed technical requirements and operational rules for the collection of the API data referred to in Article 4(2), points (a) to (d), using automated means in accordance with paragraph 2 and 3 of this Article, including on requirements for data security.

RemovedArticle 6 – paragraph 1: 1. Air carriers shall transfer the encrypted API data to the router by electronic means. They shall do so in accordance with the detailed rules referred to in paragraph 3, once such rules have been adopted and are applicable.

RemovedArticle 6 – paragraph 2: 2. Air carriers shall transfer the API data both at the moment of check-in and immediately after flight closure, that is, once the passengers have boarded the aircraft in preparation for departure and it is no longer possible for passengers to board or to leave the aircraft. At the moment of check-in, air carriers shall transfer the API data in accordance with this Regulation and relevant international standards. Air carriers shall receive an acknowledgement of receipt of the transfer of the API data.

RemovedArticle 6 – paragraph 3: 3. The Commission is empowered to adopt delegated acts in accordance with Article 37 to supplement this Regulation by laying down the necessary detailed rules on the common protocols and supported data formats to be used for the encrypted transfers of API data to the router referred to in paragraph 1, including the transfer of API data at the moment of check-in, the meaningful reply and requirements for data security. Such detailed rules shall ensure that airlines transmit API data using the same structure and content.

RemovedArticle 6 – paragraph 4: deleted

RemovedArticle 7 – paragraph 1 a (new): The competent border authorities shall be prohibited from processing API data for the purposes of profiling under any circumstances.

RemovedArticle 8 – paragraph 1: 1. Air carriers shall store, for a time period of 24 hours from the moment of departure of the flight, the API data relating to that passenger that they collected pursuant to Article 4. They shall immediately and permanently delete that API data after the expiry of that time period. This shall be without prejudice to the possibility for air carriers to retain and use the data where necessary for the normal course of their business, in particular for travel facilitation, in compliance with the applicable law and in particular Regulation (EU) 2016/679.

RemovedArticle 8 – paragraph 2: 2. The competent border authorities shall store, for a time period of 24 hours from the moment of departure of the flight, the API data relating to that passenger that they received through the router pursuant to Article 11. They shall immediately and permanently delete that API data after the expiry of that time period.

RemovedArticle 8 – paragraph 2 a (new): 2a. Air carriers or competent border authorities shall immediately either correct, complete or update, or permanently delete, the API data concerned in both of the following situations: / (a) where they become aware that the API data collected is inaccurate, incomplete or no longer up-to-date; / (b) where the transfer of the API data in accordance with Article 5(2) has been completed.

RemovedArticle 8 – paragraph 2 b (new): 2b. Air carriers or competent border authorities shall immediately and permanently delete API data where they become aware that the API data collected was processed unlawfully or that the data transferred does not constitute API data.

RemovedArticle 8 – paragraph 2 c (new): 2c. Where the air carriers become aware of the circumstances referred to in point (a) of paragraph 2a or paragraph 2b after having completed the transfer of the data in accordance with Article 6(1), they shall immediately inform the European Union Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA). Upon receiving such information, eu-LISA shall immediately inform the competent border authority that received the API data transmitted through the router.

RemovedArticle 8 – paragraph 3: deleted

RemovedArticle 8 a (new): Article 8a / Fundamental Rights / 1. Collection and processing of personal data in accordance with this Regulation and Regulation (EU) [API law enforcement] by air carriers and competent authorities shall not result in discrimination against persons on the grounds of sex and gender, race, colour, ethnic or social origin, genetic features, language, religion or belief, political or any other opinion, membership of a national minority, property, birth, disability, age or sexual orientation. / 2. This Regulation shall fully respect human dignity and the fundamental rights and principles recognised by the Charter, including the right to respect for one’s private life, to asylum, to the protection of personal data, to freedom of movement and to effective legal remedies. / 3. Particular attention shall be paid to children, the elderly, persons with a disability and vulnerable persons. The best interests of the child shall be a primary consideration when implementing this Regulation.

RemovedArticle 9 – paragraph 1: 1. eu-LISA shall design, develop, host and technically manage, in accordance with Articles 22 and 23, a router for the purpose of facilitating the transfer of encrypted API data by the air carriers to the competent border authorities in accordance with this Regulation.

RemovedArticle 9 – paragraph 2 – point b: (b) a secure communication channel between the central infrastructure and the competent border authorities and a secure communication channel between the central infrastructure and the air carriers, for the transfer and transmission of API data and for any communications relating thereto.

RemovedArticle 9 – paragraph 2 a (new): 2a. The router shall allow for the reception and transmission of encrypted API data.

RemovedArticle 9 – paragraph 2 b (new): 2b. The router shall automatically extract and make available the statistics, in accordance with Article 31, to the central repository for reporting and statistics.

RemovedArticle 9 – paragraph 3: 3. Without prejudice to Article 10 of this Regulation, the router shall, if appropriate and to the extent technically possible, share and re-use the hardware and software components, of the web service referred to in Article 13 of Regulation (EU) 2017/2226 of the European Parliament and of the Council48 , the carrier gateway referred to in Article 6(2), point (k), of Regulation (EU) 2018/1240, and the carrier gateway referred to in Article 2a, point (h), of Regulation (EC) 767/2008 of the European Parliament and of the Council49 . eu-LISA shall design the router, to the extent technically and operationally possible, in a way that is coherent and consistent with the obligations put on air carriers by Regulations (EU) 2017/2226, (EU) 2018/1240 and (EC) 767/2008.

RemovedArticle 9 – paragraph 3 a (new): 3a. eu-LISA shall design and develop the router in a way that any API data transferred from the air carriers to the router in accordance with Article 6 and any API data transmitted from the router to the competent border authorities in accordance with Article 11 and to the central repository for reporting and statistics in accordance with Article 31(2) are encrypted.

RemovedArticle 10 – paragraph 1: Notwithstanding the use of the router in Article 4b (new) of Regulation (EU) [API law enforcement], the router shall only be used: / (a) by air carriers to transfer encrypted API data in accordance with this Regulation; / (b) by the competent border authorities to receive encrypted API data in accordance with this Regulation.

RemovedArticle 10 a (new): Article 10a / Data format and transfer verifications / 1. The router shall, in an automated manner and based on real-time flight traffic data, verify whether the air carrier transferred the API data in accordance with Article 6(1). / 2. The router shall, immediately and in an automated manner, verify whether the API data transferred to it in accordance with Article 6(1) complies with the detailed rules on the supported data formats, referred to in Article 6(3). / 3. Where the router has verified in accordance with paragraph 1 that the data was not transferred by the air carrier or where the data in question is not compliant with the detailed rules referred to in paragraph 2, the router shall, immediately and in an automated manner, notify the air carrier concerned and the competent border authorities of the Member States to which the data were to be transmitted pursuant to Article 11(1). In this case, the air carrier shall immediately transfer the API data in accordance with Article 6. / 4. The Commission shall adopt implementing acts specifying the necessary detailed technical and procedural rules for the verifications and notifications referred to in paragraphs 1, 2 and 3 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 36(2).

RemovedArticle 11 – paragraph 1 – subparagraph 1: Upon the verifications referred to in Article 10a, the router shall, immediately and in an automated manner, transmit the encrypted API data, transferred to it pursuant to Article 6, to the competent border authorities of the Member State referred to in Article 4(3), point (c). It shall do so in accordance with the detailed rules referred to in paragraph 4 of this Article, once such rules have been adopted and are applicable.

RemovedArticle 11 – paragraph 3: 3. The Member States shall ensure that only the duly authorised and trained staff of the competent border authorities, designated in accordance with paragraph 2, have access to the API data transmitted to them through the router. They shall lay down the necessary rules to that effect. Those rules shall include rules on the creation and regular update of a list of those staff and their profiles.

RemovedArticle 11 – paragraph 4: 4. The Commission is empowered to adopt delegated acts in accordance with Article 37 to supplement this Regulation by laying down the necessary detailed technical and procedural rules for the transmissions of encrypted API data from the router referred to in paragraph 1, including on requirements for data security.

RemovedArticle 12 – paragraph 1 – introductory part: API data, transferred to the router pursuant to this Regulation, shall be stored on the router only insofar as necessary to complete the transmission to the relevant competent borders authorities and shall be deleted from the router, immediately, permanently and in an automated manner, in both of the following situations:

RemovedArticle 12 – paragraph 1 – point a: (a) where the transmission of the API data to the relevant competent border authorities has been completed;

RemovedArticle 12 – paragraph 1 – point a a (new): (aa) in cases of technical impossibility of the router to subsequently transmit the API data to the competent border authorities, after 12 hours.

RemovedArticle 12 – paragraph 1 – point b: deleted

RemovedArticle 13 – paragraph 1 – subparagraph 1 – introductory part: eu-LISA shall keep logs of all processing operations relating to the transfer of API data through the router under this Regulation. Those logs shall cover:

RemovedArticle 13 – paragraph 1 – subparagraph 1 – point b: (b) the competent border authorities to which the API data was transmitted through the router;

RemovedArticle 13 – paragraph 2: 2. Air carriers shall create logs of all processing operations under this Regulation undertaken by using the automated means referred to in Article 5(2). Those logs shall cover the date, time and place of transfer of the API data. Those logs shall not contain any personal data, other than the information necessary to identify the relevant member of the staff of the air carrier.

RemovedArticle 13 – paragraph 3: 3. The logs referred to in paragraphs 1 and 2 shall be used only for ensuring the security and integrity of the API data and the lawfulness of the processing, in particular as regards compliance with the requirements set out in this Regulation, including proceedings for penalties for infringements of those requirements in accordance with Articles 29 and 30 of this Regulation.

RemovedArticle 13 – paragraph 4: 4. eu-LISA and air carriers shall take appropriate measures to protect the logs that they created pursuant to paragraphs 1 and 2, respectively, against unauthorised access and other security risks.

RemovedArticle 13 – paragraph 4 a (new): 4a. The national supervisory authorities referred to in Article 29 and competent authorities shall have access to the relevant logs referred to in paragraph 1 where necessary for the purposes referred to in paragraph 3.

RemovedArticle 13 – paragraph 5 – subparagraph 2: However, if those logs are needed for procedures for monitoring or ensuring the security and integrity of the API data or the lawfulness of the processing operations, as referred to in paragraph 2, and these procedures have already begun at the moment of the expiry of the time period referred to in the first subparagraph, eu-LISA and the air carriers may keep those logs for as long as necessary for those procedures, provided that eu-LISA or the air carriers inform the Commission of the need to keep those logs and provide reasons for doing so. In that case, they shall immediately delete those logs when they are no longer necessary for those procedures.

RemovedArticle 15 – paragraph 1: The competent border authorities shall be controllers, within the meaning of Article 4, point (7), of Regulation (EU) 2016/679, in relation to the processing of API data constituting personal data through the router, including the transmission of the data from the router to the authorities and the storage for technical reasons of that data in the router, as well as in relation to their processing of API data constituting personal data referred to in Article 7 of this Regulation.

RemovedArticle 16 – paragraph 1: eu-LISA shall be the processor on behalf of the competent border authorities within the meaning of Article 3, point (12), of Regulation (EU) 2018/1725 for the processing of API data constituting personal data through the router in accordance with this Regulation.

RemovedArticle 16 a (new): Article16a / Information to passengers / In accordance with the right of information in Article 13 of Regulation (EU) 2016/679, air carriers shall provide passengers, on flights covered by this Regulation, with information on the purpose of the collection of their personal data, the type of personal data collected, the recipients of the personal data and the means to exercise the data subject rights. / This information shall be communicated to passengers in writing and in an easily accessible format at the moment of booking and at the moment of check-in, irrespective of the means used to collect the personal data at the moment of check-in in accordance with Article 5.

RemovedArticle 17 – paragraph -1 (new): -1. Competent border authorities and air carriers shall ensure the security of the API data, in particular API data constituting personal data, that they process pursuant to this Regulation.

RemovedArticle 17 – paragraph -1 a (new): -1a. Competent border authorities and air carriers shall cooperate, in accordance with their respective responsibilities and in compliance with Union law, with each other and with eu-LISA to ensure such security.

RemovedArticle 17 – paragraph 1: 1. eu-LISA shall ensure the security and encryption of the API data, in particular API data constituting personal data, that it processes pursuant to this Regulation. The competent border authorities and the air carriers shall ensure the security of the API data, in particular API data constituting personal data, that they process pursuant to this Regulation. eu-LISA, the competent border authorities and the air carriers shall cooperate, in accordance with their respective responsibilities and in compliance with Union law, with each other to ensure such security.

RemovedArticle 17 – paragraph 2 – subparagraph 1 – point c: (c) ensure that it is possible to verify and establish to which competent border authorities the API data is transmitted through the router;

RemovedArticle 18 – paragraph 1: The air carriers and competent authorities shall monitor their compliance with their respective obligations under this Regulation, in particular as regards their processing of API data constituting personal data, including through frequent verification of the logs in accordance with Article 13.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
28 September 2026

Cite as

European Parliament (2024). “Changes between A-9-2023-0409 and TA-9-2024-0376”. Text, 25 April 2024. from A-9-2023-0409, to TA-9-2024-0376. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0409/compare/TA-9-2024-0376?all=1&part=2 (retrieved 28 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-04-25,
  author = {{European Parliament}},
  title = {{Changes between A-9-2023-0409 and TA-9-2024-0376}},
  year = {2024},
  date = {2024-04-25},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0409/compare/TA-9-2024-0376?all=1&part=2}},
  url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0409/compare/TA-9-2024-0376?all=1&part=2},
  urldate = {2026-09-28},
  publisher = {EU Parl Watch Research},
  note = {Text. from A-9-2023-0409, to TA-9-2024-0376. Data: European Parliament Open Data (CC BY 4.0)}
}